Root-cause patch that restricts directive signing to explicitly deferred directives (like inlinecss), preventing signatures on unresolved directives exploited in the StyleSmuggler chain. Includes ready-to-apply patches for versions 2.4.5–2.4.9 and instructions for using composer-patches/cweagans.
Three bash scripts to scan for IoCs and guide cleanup on servers, apply community mitigations via Composer patches and a hardening module, and remotely check GraphQL exposure. Includes DDEV/Warden support, cloud-friendly usage, and step-by-step confirmations.
Provides per-package patch sets for the July 2026 security release, compatible with cweagans/composer-patches, covering 2.4.6-p15, 2.4.7-p10, 2.4.8-p5, and 2.4.9 (including B2B). Includes composer.json snippets, application steps, and notes on nginx.conf.sample and the omitted patch-status script.